properfraction kayıtları
properfraction üreticisine ait 35 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %42,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-269 Improper Privilege Management3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-862 Missing Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-502 Deserialization of Untrusted Data1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
35 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2021-34621Kavram kanıtı | ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalationproperfraction · profilepress · CWE-269 | Kritik9,8 | — | %68,9 | 7 Tem 2021 |
41Planlayın | CVE-2021-34624Kavram kanıtı | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Componentproperfraction · profilepress · CWE-434 | Kritik9,8 | — | %6,7 | 7 Tem 2021 |
40Planlayın | CVE-2021-34623İstismar yok | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Componentproperfraction · profilepress · CWE-434 | Kritik9,8 | — | %2,1 | 7 Tem 2021 |
39İzleyin | CVE-2024-9947İstismar yok | ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth providerproperfraction · profilepress · CWE-287 | Kritik9,8 | — | %0,5 | 23 Eki 2024 |
36İzleyin | CVE-2021-34622Kavram kanıtı | ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalationproperfraction · profilepress · CWE-269 | Yüksek8,8 | — | %4,1 | 7 Tem 2021 |
34İzleyin | CVE-2023-41954Kavram kanıtı | WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerabilityproperfraction · profilepress · CWE-269 | Yüksek8,6 | — | %1,2 | 17 May 2024 |
30İzleyin | CVE-2023-44150İstismar yok | WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposureproperfraction · profilepress · CWE-200 | Yüksek7,5 | — | %0,7 | 30 Kas 2023 |
28İzleyin | CVE-2022-45083İstismar yok | WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injectionproperfraction · profilepress · CWE-502 | Yüksek7,2 | — | %0,6 | 19 Oca 2024 |
24İzleyin | CVE-2021-24522Kavram kanıtı | ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widgetproperfraction · profilepress · CWE-79 | Orta6,1 | — | %1,6 | 9 Ağu 2021 |
24İzleyin | CVE-2024-1519İstismar yok | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-Sproperfraction · profilepress · CWE-79 | Orta6,1 | — | %0,6 | 28 Şub 2024 |
24İzleyin | CVE-2023-23830İstismar yok | WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Orta6,1 | — | %0,4 | 3 May 2023 |
24İzleyin | CVE-2022-47444İstismar yok | WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Orta6,1 | — | %0,4 | 29 Mar 2023 |
21İzleyin | CVE-2024-1408İstismar yok | ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcodeproperfraction · profilepress · CWE-79 | Orta5,4 | — | %0,6 | 28 Şub 2024 |
21İzleyin | CVE-2024-1535İstismar yok | ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeproperfraction · profilepress · CWE-79 | Orta5,4 | — | %0,6 | 13 Mar 2024 |
21İzleyin | CVE-2024-1806İstismar yok | ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcodeproperfraction · profilepress · CWE-79 | Orta5,4 | — | %0,6 | 13 Mar 2024 |
21İzleyin | CVE-2023-50882İstismar yok | WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerabilityproperfraction · profilepress · CWE-862 | Orta5,3 | — | %0,5 | 9 Ara 2024 |
21İzleyin | CVE-2024-1570İstismar yok | ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeproperfraction · profilepress · CWE-79 | Orta5,4 | — | %0,5 | 28 Şub 2024 |
21İzleyin | CVE-2024-1409İstismar yok | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Orta5,4 | — | %0,4 | 13 Mar 2024 |
21İzleyin | CVE-2024-3210İstismar yok | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Orta5,4 | — | %0,4 | 10 Nis 2024 |
21İzleyin | CVE-2023-41953İstismar yok | WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerabilityproperfraction · profilepress · CWE-862 | Orta5,3 | — | %0,4 | 9 Ara 2024 |
21İzleyin | CVE-2023-23820İstismar yok | WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Orta5,4 | — | %0,4 | 3 May 2023 |
21İzleyin | CVE-2024-11083İstismar yok | ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposureproperfraction · profilepress · CWE-200 | Orta5,3 | — | %0,4 | 27 Kas 2024 |
21İzleyin | CVE-2024-2867İstismar yok | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-20 | Orta5,4 | — | %0,4 | 2 May 2024 |
21İzleyin | CVE-2024-1046İstismar yok | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Orta5,4 | — | %0,4 | 5 Şub 2024 |
21İzleyin | CVE-2024-2861İstismar yok | ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widgetproperfraction · profilepress · CWE-79 | Orta5,4 | — | %0,3 | 23 May 2024 |
- CVE-2021-3462160Bu hafta
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
KritikCVSS 9,8Kavram kanıtıEPSS %69properfraction · profilepress7 Tem 2021
- CVE-2021-3462441Planlayın
ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component
KritikCVSS 9,8Kavram kanıtıEPSS %7properfraction · profilepress7 Tem 2021
- CVE-2021-3462340Planlayın
ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Component
KritikCVSS 9,8İstismar yokEPSS %2properfraction · profilepress7 Tem 2021
- CVE-2024-994739İzleyin
ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider
KritikCVSS 9,8İstismar yokEPSS %1properfraction · profilepress23 Eki 2024
- CVE-2021-3462236İzleyin
ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation
YüksekCVSS 8,8Kavram kanıtıEPSS %4properfraction · profilepress7 Tem 2021
- CVE-2023-4195434İzleyin
WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
YüksekCVSS 8,6Kavram kanıtıEPSS %1properfraction · profilepress17 May 2024
- CVE-2023-4415030İzleyin
WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure
YüksekCVSS 7,5İstismar yokEPSS %1properfraction · profilepress30 Kas 2023
- CVE-2022-4508328İzleyin
WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection
YüksekCVSS 7,2İstismar yokEPSS %1properfraction · profilepress19 Oca 2024
- CVE-2021-2452224İzleyin
ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widget
OrtaCVSS 6,1Kavram kanıtıEPSS %2properfraction · profilepress9 Ağu 2021
- CVE-2024-151924İzleyin
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-S
OrtaCVSS 6,1İstismar yokEPSS %1properfraction · profilepress28 Şub 2024
- CVE-2023-2383024İzleyin
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0properfraction · profilepress3 May 2023
- CVE-2022-4744424İzleyin
WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0properfraction · profilepress29 Mar 2023
- CVE-2024-140821İzleyin
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode
OrtaCVSS 5,4İstismar yokEPSS %1properfraction · profilepress28 Şub 2024
- CVE-2024-153521İzleyin
ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %1properfraction · profilepress13 Mar 2024
- CVE-2024-180621İzleyin
ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode
OrtaCVSS 5,4İstismar yokEPSS %1properfraction · profilepress13 Mar 2024
- CVE-2023-5088221İzleyin
WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %1properfraction · profilepress9 Ara 2024
- CVE-2024-157021İzleyin
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0properfraction · profilepress28 Şub 2024
- CVE-2024-140921İzleyin
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) S
OrtaCVSS 5,4İstismar yokEPSS %0properfraction · profilepress13 Mar 2024
- CVE-2024-321021İzleyin
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) S
OrtaCVSS 5,4İstismar yokEPSS %0properfraction · profilepress10 Nis 2024
- CVE-2023-4195321İzleyin
WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0properfraction · profilepress9 Ara 2024
- CVE-2023-2382021İzleyin
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %0properfraction · profilepress3 May 2023
- CVE-2024-1108321İzleyin
ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
OrtaCVSS 5,3İstismar yokEPSS %0properfraction · profilepress27 Kas 2024
- CVE-2024-286721İzleyin
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) S
OrtaCVSS 5,4İstismar yokEPSS %0properfraction · profilepress2 May 2024
- CVE-2024-104621İzleyin
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) S
OrtaCVSS 5,4İstismar yokEPSS %0properfraction · profilepress5 Şub 2024
- CVE-2024-286121İzleyin
ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget
OrtaCVSS 5,4İstismar yokEPSS %0properfraction · profilepress23 May 2024